Thailand’s Personal Data Protection Act (PDPA) B.E. 2562 is the country’s primary data protection law that governs how organizations must collect, use, disclose, store, transfer, and safeguard personal data. The law aims to give individuals more control over their data while ensuring that businesses operate with transparency, accountability, and strong security measures.
To help organizations meet these obligations, ManageEngine offers a comprehensive suite of IT management and security solutions that strengthen data protection, enhance internal governance, and support PDPA compliance across the entire data life cycle. Our solutions enable you to enforce access controls, secure sensitive information, monitor data activities, automate compliance processes, and respond effectively to data subject requests.
Whether you are managing identities, securing endpoints, monitoring logs, handling incidents, or protecting sensitive assets, ManageEngine equips you with the tools required to build a secure, resilient, and PDPA-ready environment.
The PDPA directly shapes how organizations manage and protect personal data across IT
environments. It sets clear requirements for security controls, access management,
record-keeping, and transparency—compelling IT teams to build systems that are secure
by design and aligned with legal obligations.
The PDPA requires organizations to define how personal data is collected, used, stored, and deleted.
IT teams must implement:
This ensures transparency and proper accountability.
An organization’s IT teams plays a central role in preventing data breaches for that organization.
The PDPA requires:
This pushes IT teams to proactively secure all systems that store or process personal data.
The PDPA mandates that only authorized personnel can access personal data.
The IT team must enable:
This reduces risk from insider threats and unauthorized access.
The law grants individuals rights such as access, rectification, portability, and deletion.
IT systems must be capable of:
These capabilities require proper system design and integration.
If personal data is transferred abroad, IT teams must ensure:
The PDPA requires organizations to show evidence of compliance.
IT systems must:
This helps organizations respond to regulatory inquiries and assess internal risks.
DPOs rely heavily on IT systems to:
IT teams provide the technical foundation needed for DPO oversight.
Personal data must be used only for the purposes communicated to the data subject.
Only the minimum necessary personal data may be collected or stored.
If personal data is collected from sources other than the data subject, the controller must ensure transparency and lawful basis.
Sensitive personal data requires explicit consent and strong protection.
Organizations within the same group may transfer data internationally under an approved internal policy.
Individuals may request access to their personal data.
Individuals may request their personal data in a structured, machine-readable format.
Individuals may object to certain types of data processing.
Individuals may request deletion, destruction, or anonymization of personal data.
Processing of personal data must be temporarily halted when requested.
Organizations must ensure personal data is accurate and up to date.
If a correction request is denied, the organization must record the request and the reason.
Organizations must implement security measures, access control, risk management, and incident response.
Processors must follow the controller’s instructions and safeguard personal data.
Organizations must designate a DPO to oversee compliance and monitor processing activities.
Talk to our experts to get more information on how your organization can comply with the PDPA.
The Personal Data Protection Committee (PDPC) is the regulatory authority established under Thailand’s Personal Data Protection Act B.E. 2562. It operates through its secretariat office, the Office of the Personal Data Protection Committee (OPDPC).
The PDPC’s core responsibilities include:
Issuing guidelines: Setting standards, regulations, and best practices for personal data handling across industries.
Supervision and enforcement: Investigating and taking action against data controllers and processors that violate the law.
Handling complaints: Receiving and adjudicating complaints from data subjects whose rights have been infringed.
Advisory support: Providing guidance and resources to help organizations achieve compliance.
Thailand’s PDPA has been fully enforceable since June 1, 2022. It applies to any organization—Thai or foreign—that collects, uses, or discloses personal data of individuals in Thailand.
PDPA defines clear roles with distinct responsibilities for anyone who touches personal data:
Data controller: The person or organization that determines the purposes and means of collecting and using personal data. This is typically the company itself (e.g., an e-commerce platform storing customer data).
Data processor: A person or organization that processes data on behalf of and under the instructions of a data controller. Examples include cloud providers, HR outsourcing firms, and third-party analytics vendors.
Data protection officer (DPO): Certain organizations are required by law to appoint a DPO, particularly those that process sensitive personal data at scale or conduct large-scale systematic monitoring.
Data subjects (individuals): Customers and the public gain enforceable rights: the right to access, rectify, delete, restrict, and object to the use of their personal data.
Organizations (data controllers): Reduced legal liability, stronger customer relationships, and a more mature internal data governance culture.
Business partners and suppliers: Clear contractual frameworks for data sharing reduce ambiguity and disputes in B2B relationships.
Investors: Organizations with solid compliance postures present lower regulatory risk profiles, making them more attractive for investment.
Thailand’s digital economy: Broad adoption of PDPA principles builds systemic trust in digital services, accelerating adoption and growth.
The PDPA establishes three tiers of penalties:
Administrative fine: Up to THB 5,000,000.
Civil damages (punitive): Up to two times the cost of the actual damages.
Criminal imprisonment (up to one year): Criminal fine (combined) up to THB 1,000,000.
The most severe penalties apply to unauthorized collection of sensitive personal data and using personal data for personal gain or unauthorized disclosure to third parties. Directors and senior executives can be held personally liable if found to have consented to or been complicit in a violation.
The complete implementation of PDPA requires a combination of governance processes and policies, as well as people, technical and organizational measures. The features and capabilities described above represent some of the ways in which our solutions may support organizations in meeting certain PDPA requirements.
Organizations should conduct their own independent assessment of how these solutions align with their specific needs and help achieve compliance with this law.
This material is provided for informational purposes only and should not be construed as legal advice or a guarantee of compliance with the PDPA. ManageEngine makes no warranties, whether express, implied or statutory about the information in this material. Please consult your legal advisor to understand how PDPA applies to your organization and steps required to comply with its obligations.